The short version
- Your diary is local-first. The main health database is encrypted on your device. Nurelio does not maintain a cloud account containing a copy of that database.
- Some data leaves your device. Food lookups, AI features, subscriptions, sign-in and diagnostics involve our servers or service providers.
- AI is on by default; product analytics is not. By using the app you agree to the AI features described below, and you can switch them off at any time in Settings. Product analytics requires opt-in. Website analytics stays off until you accept; we do not record website or app sessions.
- We do not sell personal information or share it for targeted advertising.
Our separate Consumer Health Data Privacy Policy explains consumer health data practices and rights.
Who is responsible
Dzmitry Tselabionak, operating as Nurelio (“we”, “us”), is responsible for the personal information described here. Our privacy contact is privacy@nurelio.app, reachable at privacy@nurelio.app.
This policy covers the Nurelio app and website. The app is intended for adults aged 18 and over. Our intended launch markets are Canada, Australia, the United Kingdom and the United States; actual availability is shown in the App Store.
Information on your device
Your main encrypted database holds your meals, nutrition, water, weight, activity, feelings, symptoms, goals, profile answers, conversations and derived insights. Your device also holds settings, credentials and feature caches. The database key is stored in the iOS Keychain; this does not mean every app file or exported copy has the database’s encryption protection.
Local storage does not mean information is never collected or processed. The app processes it to provide the features you use. Some information is transmitted as explained below. Device backups, exports and Apple Health may create additional copies under your or Apple’s control.
Information handled outside your device
- Sign-in and account linking: sign-in providers may supply your name, email and profile image. We handle account-linking details, including an Apple refresh token and email when provided, to support sign-in and revoke access when an account is deleted. Purchases are associated with a random app identifier; signing in does not back up your diary.
- Marketing: if you subscribe, we store your email, any supplied name, consent status, source and consent timestamps. We use these to manage product updates and withdrawals, separately from your diary.
- Food searches: search text, barcodes and the food details needed to identify an item are sent to our backend and, where needed, food-data services. These requests can reveal information about eating habits.
- AI features: the inputs and health context described below are transmitted to generate a response, unless you switch AI off.
- Subscription and transaction information: the App Store and RevenueCat process purchase identifiers, entitlement status and related technical information. We do not receive your full payment-card details.
- Optional product analytics: feature usage, screen names and counts linked to a random identifier. This is pseudonymous, not anonymous. We exclude diary values and contact details from these events.
- Diagnostics and security: error reports, app/device information, network addresses, request timing, routes, app-integrity checks and random identifiers help us troubleshoot and prevent abuse. We configure diagnostics to exclude health content. Hosting and network providers also process technical connection data.
- Support and privacy requests: we receive your message, reply address and anything you choose to include. Please avoid sending your diary or sensitive attachments unless necessary.
AI processing
Food AI, the coach and the score summary are part of the app. By using Nurelio you accept our Terms and agree to the AI processing described in this section, including the health information listed below. These features are enabled by default.
You can switch AI off at any time in Settings → Privacy & permissions. Switching it off stops new AI requests and hides the features that need them; manual logging, catalog search and on-device insights keep working. It does not reverse processing already performed. You do not have to give up the rest of the app to refuse AI.
- Food AI: the description, dictated text or photo you submit is sent to identify food and estimate nutrition. Dictation is transcribed on the device; Nurelio sends the resulting text, not the audio, for food analysis.
- Coach: your messages, conversation history, saved memories, recent diary and relevant profile details are sent when you ask a question. Context can include recent food names and totals, feelings, symptoms, water, steps, sleep, workouts, scores, targets, age, sex, height, weight, diet, allergies and declared health conditions.
- Score summary: similar context may be sent automatically when you view the feature, unless you have switched AI off, once sufficient logged data is available. A cached summary reduces repeat requests; failed requests or a cleared cache may cause another request.
We do not deliberately add your account name, email or account ID to AI context. However, free text, memories and photos can contain identifying information you include. Do not include names, contact details, faces or other people’s information unless needed and you have authority to share it.
Production AI requests go through our backend to OpenRouter and its model-hosting providers. Our requests require endpoints with zero-data-retention policies and disallow provider data collection for training. If no eligible route is available, the AI request fails rather than falling back to direct Google processing. We do not write AI request content or responses to our server database or use them to train our own models.
These routing controls concern request content. They do not mean that no technical metadata exists, that processing stays in your country, or that security and lawful-disclosure risks disappear. Providers can maintain operational metadata under their applicable policies. See OpenRouter’s retention controls and privacy policy.
You can use manual logging, catalog searches and on-device calculations with AI switched off. Some of these non-AI features still make the network requests described in this policy.
Apple Health, backups and exports
With your Health permissions, Nurelio reads supported health signals and can write supported nutrition and related entries to Apple Health. Review or revoke these permissions in Apple’s Health settings. Apple controls its Health storage and any iCloud synchronization under your settings and its policies.
An exported file or device backup is a separate copy. Deleting Nurelio does not necessarily delete Apple Health records, iCloud or device backups, exported files, or information held by providers. Manage those copies separately. Apple Health is not a complete backup of your Nurelio diary, settings or conversations.
Analytics and website storage
Product analytics in the app requires opt-in and can be withdrawn in Settings. We use PostHog’s EU service. Random identifiers allow events to be associated over time; omitting names does not make them anonymous. Feature names and app usage can still reveal an interest in nutrition or wellbeing.
The website does not initialize PostHog or send product analytics before you accept. Declining leaves it off. If you accept, PostHog records visits and selected clicks and stores a browser identifier. Session replay is disabled. We do not use advertising or cross-site tracking SDKs.
Use Privacy settings in the website footer to change your choice at any time. We store a small preference record so the site can remember your decision. Withdrawing stops new analytics and clears active analytics persistence; it does not itself erase events already received. Clearing site storage resets your choice. Essential hosting, security and requests you initiate, such as a newsletter subscription, still operate.
Emails
Product updates require a separate opt-in. You can unsubscribe using the link in an email, through app settings where available, or by contacting us. Necessary replies about support, privacy requests or service administration are separate from marketing.
After withdrawal, we may retain a limited suppression record to prevent further marketing. For an erasure request we may need to verify control of the address before deleting records. An unverified address associated with an app deletion is suppressed rather than automatically erased; contact us to complete verification.
Recipients and purposes
- Cloudflare: website hosting, backend processing, security and limited account/marketing records.
- OpenRouter and model-hosting providers: AI processing as described above.
- Food-data services: food identification and nutrition lookups; sources are listed on our Data sources page.
- PostHog EU: consented product analytics.
- Sentry: diagnostics and error monitoring.
- RevenueCat and Apple: subscription management, billing and purchase restoration.
- Apple and Google: sign-in if selected; Apple also provides Health and app-integrity services.
- Email and support providers: delivering requested communications and handling correspondence when used.
Service providers process information to perform their services. Some, such as app stores and sign-in providers, also act independently under their own privacy policies. We may disclose information where legally required or necessary to protect rights and safety, subject to applicable law. We do not sell personal information or share it for targeted advertising.
Legal bases and international processing
Where UK data-protection law applies, we rely on contract necessity for requested service functionality, consent for optional analytics and marketing, and legitimate interests for proportionate security, fraud prevention and troubleshooting. For off-device AI processing of health information we rely on your consent, given by accepting our Terms when you use the app and withdrawable through the AI switch in Settings, alongside the applicable Article 6 basis. Health information may require additional consent or another permitted basis in other jurisdictions. We process information to comply with legal obligations where required.
Providers may process information outside your country, including in the United States and the European Union. Temporary processing can still be an international transfer. Where required, transfers must have an applicable adequacy basis or appropriate safeguards, such as approved contractual clauses and any necessary supplementary measures. Contact our privacy contact for information about the safeguards applicable to your information and how to obtain a copy. This policy is not itself a transfer agreement or consent to a restricted transfer.
Retention
Local diary records remain until you delete or replace them. Separate caches and backups can have different lifetimes. We retain account-linking records while needed to provide and administer the account; marketing preferences while needed to honor your choice; and correspondence while needed to resolve a request and document the response.
Analytics, diagnostics and technical records are retained for the period needed for usage measurement, troubleshooting, abuse prevention and security, subject to configured provider retention limits and applicable deletion rights. Retention decisions take account of whether a record is still needed for an unresolved issue, a legal obligation or a legal claim. AI content handling is described above; it is distinct from operational metadata. We delete or de-identify records when these purposes no longer require personal information.
Your rights and complaints
Depending on your location and the law’s applicability, you may request access, correction, deletion, portability, restriction, objection, information about recipients, and withdrawal of consent. You may complain to a regulator without contacting us first. We do not retaliate for exercising privacy rights; withdrawing an optional permission can make the dependent feature unavailable.
For local records, use the app’s editing, export and deletion tools. Account deletion attempts remote erasure before clearing the local account; if it cannot complete, the app keeps your local data and identifier so you can retry. Provider processing and any required identity verification may take additional time. Deleting the app alone does not submit a server-side erasure request or cancel a subscription.
Email privacy@nurelio.app to exercise rights or appeal a decision. We may request proportionate verification or proof of an authorized agent’s authority, but do not require unrelated health information. We respond within the deadline applicable to your request and explain any permitted extension, refusal or retention exception. An initial rights request is generally free; any legally permitted exception will be explained in advance.
Relevant authorities include the UK ICO, the Office of the Privacy Commissioner of Canada, provincial privacy authorities including Quebec’s Commission d’accès à l’information, the Australian OAIC, and your US state attorney general. Consumer health rights and appeals are detailed in our separate policy.
Security and health information
We use encrypted transport, encryption for the main on-device database, access controls and data minimization. No system is perfectly secure; local-first architecture reduces some risks but does not eliminate breaches or lawful disclosure obligations.
Nurelio is a general wellbeing service, not a medical provider. Information in the app is not a medical record managed by a healthcare professional. HIPAA does not automatically apply to a consumer app; other privacy, security and breach-notification laws may apply. We assess security incidents and provide notifications where required by law.
Children and changes
Nurelio is not intended for people under 18. If you believe a minor has provided personal information, contact us so we can investigate and take appropriate deletion or restriction measures.
We will update the date when this policy changes. We will give appropriate notice of material changes before they take effect, except where an urgent legal or security reason requires an earlier change. Where a change requires new consent, we will obtain it before the new processing begins.